Electronic Lock Controller Self-Provisioning via Digital Certificate

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing electronic lock controllers face security concerns due to potential unauthorized access to cryptographic keys at the manufacturing facility, reuse of keys across multiple devices, and the complexity of ensuring unique hardware identifiers and keys.

Innovation Solution

An electronic lock controller is prepared with digitally signed lock information and self-provisioning instructions to obtain a digital certificate from a trusted server, ensuring unique cryptographic keys and identifiers without direct involvement from the manufacturing facility, using a mobile device or direct communication for verification.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If cryptographic keys are provided at the manufacturing facility, then the electronic lock controller can be securely provisioned, but unauthorized access to keys may occur and keys may be reused across multiple devices

Engineering Contradiction:
Improvesecurity of cryptographic keysVSAvoidunauthorized access and key reuse
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the key provisioning process from the manufacturing facility environment. Instead of providing keys at the factory, the system generates keys independently on the electronic lock controller and uses a digitally signed certificate from a trusted server to verify authenticity, thereby removing the vulnerable link between manufacturing facilities and key distribution.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a trusted server as an intermediary that issues digitally signed certificates to verify the authenticity of electronic lock controllers. This intermediary enables secure key verification without requiring direct access to manufacturing facilities, preventing unauthorized access and key reuse through cryptographic verification.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of manufacture

If manufacturing facility provides cryptographic keys, then provisioning can be simplified, but ensuring unique hardware identifiers and keys becomes complex

Engineering Contradiction:
Improveprovisioning processVSAvoiduniqueness of hardware identifiers and keys
Core Design Contradiction:
Ease of manufactureVSManufacturing precision

Solution Approach 1:

The electronic lock controller performs self-provisioning by independently generating its own cryptographic key pair and requesting a digitally signed certificate from a trusted server. This self-service approach eliminates the need for complex manufacturing facility involvement while ensuring each device receives unique, verified credentials.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system implements feedback through the trusted server verifying the electronic lock controller's identity and issuing a digitally signed certificate. This feedback mechanism confirms the uniqueness and authenticity of each controller's hardware identifier and cryptographic keys without requiring complex manufacturing processes.

Inventive Principle:
Principle #23Feedback

3Reliability

If digital certificates are obtained through trusted servers, then security and authenticity are enhanced, but the provisioning process becomes more complex

Engineering Contradiction:
Improveauthenticity of electronic lock controllerVSAvoidprovisioning process
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent performs preliminary actions by pre-configuring the electronic lock controller with instructions to generate cryptographic keys and communicate with the trusted server. This preparation simplifies the overall provisioning process, as the controller autonomously completes the authentication sequence without complex manual intervention.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11228453B2Secure provisioning of electronic lock controllers
Publication Date: 2022.01.18 SERA4 LTD
  • US11228453B2 patent drawing
  • US11228453B2 patent drawing
  • US11228453B2 patent drawing

AI summary

Devices, systems, and methods for preparing an electronic lock controller to obtain a digital certificate that verifies authenticity of the electronic lock controller are provided. The method involves physically marking an electronic lock controller with a mark containing digitally signed lock information. The digitally signed lock information includes a hardware identifier, and is digitally signed at a server using a private key of the server. The method further involves loading the electronic lock controller with self-provisioning instructions to cause the electronic lock controller to obtain a digital certificate that includes the public key of the electronic lock controller and the hardware identifier, the digital certificate having been signed by a private key of the server.